System Maintenance Configuring FortiGuard Services
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424 269
http://docs.fortinet.com/ • Feedback
Configuring Web Filtering and AntiSpam Options
You can access this section by selecting the expand arrow to view Web Filtering and
AntiSpam Options.
Figure 159: Web Filtering and AntiSpam Options section
Use override push IP Available only if both Use override server address and Allow Push
Update are enabled.
Select to allow you to create a forwarding policy that redirects
incoming FDS push updates to your FortiGate unit.
Enter the IP address of the NAT device in front of your FortiGate unit.
FDS will connect to this device when attempting to reach the FortiGate
unit.
The NAT device must be configured to forward the FDS traffic to the
FortiGate unit on UDP port 9443. See “Enabling push updates through
a NAT device” on page 274.
Port Select the port on the NAT device that will receive the FDS push
updates. This port must be forwarded to UDP port 9443 on the
FortiGate unit.
Available only if Use override push is enabled.
Schedule Updates Select this check box to enable scheduled updates.
Every Attempt to update once every 1 to 23 hours. Select the number of
hours between each update request.
Daily Attempt to update once a day. You can specify the hour of the day to
check for updates. The update attempt occurs at a randomly
determined time within the selected hour.
Weekly Attempt to update once a week. You can specify the day of the week
and the hour of the day to check for updates. The update attempt
occurs at a randomly determined time within the selected hour.
Update Now Select to manually initiate an FDN update.
Submit attack
characteristics…
(recommended)
Fortinet recommends that you select this check box. It helps to
improve the quality of IPS signature.
Enable Web Filter Select to enable the FortiGuard Web Filter service.
Enable Cache Select to enable caching of web filter queries.
This improves performance by reducing FortiGate unit requests to the
FortiGuard server. The cache uses 6 percent of the FortiGate memory.
When the cache is full, the least recently used IP address or URL is
deleted.
Available if Enable Web Filter is selected.
TTL Time to live. The number of seconds to store blocked IP addresses
and URLs in the cache before contacting the server again.TTL must
be between 300 and 86400 seconds.
Available only if both Enable Web Filter and Enable Cache are
selected.